
F5Certified Technology Specialist, BIG-IP DNS
Domain 2Objective 13
Objective 2.13 Explain How to Verify That DNSSEC Is Working 302 Practice Questions (Page 1)
Part of the Section 2: Deployment domain, which makes up ~30% of our current practice bank.
18questions here
4free pages
3concepts
Questions 1–5
- 1
An admin is verifying DNSSEC on a BIG-IP DNS server that hosts a signed zone. They send a query from a test workstation to the BIG-IP's IP address directly. The response has the `qr` and `aa` flags set, but no RRSIG. What does this indicate?
Select an answer first - 2
An admin is troubleshooting why DNSSEC validation fails for a zone hosted on BIG-IP DNS. They run `dig example.com A +dnssec` from a workstation and see the response has the `aa` flag set but no RRSIG for the A record. What does the presence of the `aa` flag tell them?
Select an answer first - 3
An admin is verifying that DNSSEC is working on a BIG-IP DNS server. They run `dig example.com A +dnssec` and see an RRSIG in the answer section. What does the presence of the RRSIG confirm?
Select an answer first - 4
A BIG-IP DNS admin has a signed zone that was working. After a backup restore, the zone loads but returns no RRSIGs. The admin checks the zone directory and finds the `.sig` files are present. What is the most likely issue?
Select an answer first - 5
An admin is verifying DNSSEC on a BIG-IP DNS server. They query the server for `example.com A` and receive a response with the AA bit set and an RRSIG. They want to confirm the response is from the authoritative server and not a cache. What flag should they check?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “302” is a trademark of its owner, used for identification only.